Science & methodology

Threat-intelligence discipline, applied to wrecks.

A risk score is only useful if the people acting on it can see how it was made. This page explains the WERP methodology — what goes into each number, where the data comes from, and the rules that keep inference honestly separated from observation.

The scoring model

Every wreck carries a single Risk value computed under the WERP v6 protocol from four components:

Risk = ( WCS + PHS + ESI ) × RPM
WCS — Wreck Condition Score (1–25). How likely the hull is to breach: the violence of the sinking, decades of corrosion modified by depth and water temperature, and — where a survey exists — the observed structural condition, which overrides the inference.
PHS — Pollutant Hazard Score (1–25). The wreck's fuel and cargo payload, weighted by NOAA's five-group oil classification. Documented pollutant records fully replace vessel-class defaults wherever they exist.
ESI — Environmental Sensitivity Index (1–25). The mean of five measured signals: proximity to coast, protected areas and biodiversity, coastal population, tourism use, and commercial fishing — computed from authoritative datasets, not estimated.
RPM — Release Probability Multiplier (1.0–2.0). The forward-looking amplifier: baseline environment (depth, cyclone and seismic exposure), unexploded-ordnance status, and observed stress events from live monitoring. RPM only ever amplifies — it can never push risk below the sum of the sub-scores.

Risk bands — fixed thresholds, never re-tuned to fit a distribution

Critical ≥ 110 High ≥ 75 Medium ≥ 45 Low < 45

Two phases, one honest gradient

Phase 1 — intelligence triage. The assessment is built from historical records, open-source research and archival literature, cross-referenced and hydrated against the geospatial datasets below. It is a rigorous inference — and the platform treats it as one: every unsurveyed wreck's condition and hazard scores carry an explicit deduction for not having been seen.

Phase 2 — in-water validation. Survey evidence — sonar, photogrammetry, ROV inspection — replaces inference component by component. A hull observed intact revises the condition score down; observed leaks or exposed ordnance revise scores up. Each promoted component records the survey it came from, so a reader can always distinguish what was measured from what was deduced.

The same honesty applies inside the automated pipeline: automated hazard scoring is capped below the top of its scale — the most severe ratings can only be assigned by a human analyst reviewing the evidence.

Why the deduction matters

Most wreck risk registers present archival inference with the same confidence as survey observation. WERP does not. The gap between a Phase 1 and Phase 2 score is not an error — it is the honestly-stated value of putting a survey asset in the water, and it is how the platform prioritises where surveys should go next.

Drift-aware environmental sensitivity

Earlier methodologies asked what happens to sit near a wreck. WERP v6 asks the question that actually matters: where could oil from this wreck reach? Seasonal drift-reachability envelopes — generated from operational ocean and wind models — re-ground four of the five sensitivity signals (protected areas, population, tourism, fishing) on what a release could plausibly touch, season by season. Proximity to coast deliberately remains a static measurement.

The correction runs in both directions. A wreck whose currents carry any release away from a marine protected area scores lower than a radial screen would suggest — that is a corrected over-count, not lost caution. A wreck whose seasonal drift reaches a fishery a static ring would have missed scores higher.

Data provenance

Wreck identities, coordinates and loss circumstances are cross-referenced against an authoritative Pacific WWII shipwreck reference of 902 records. Every assessed wreck's environmental context is computed — not estimated — from authoritative open datasets:

Pacific wreck register (902 records) GEBCO 2024 bathymetry GSHHG coastlines 2.3.7 WDPA protected areas GHSL population OpenStreetMap tourism Global Fishing Watch Sentinel-1 SAR via SkyTruth Cerulean USGS seismic feed NOAA NHC & GDACS storm feeds

The language model never writes a number. Narrative dossiers are machine-drafted for readability, but every score label in them is composed programmatically from the stored assessment, and every draft passes automated credibility checks — flag, loss year, vessel type, cause of loss, and consistency between stated fuel volumes and the hazard score — before it can be attached to a wreck. A draft that fails falls back to a deterministic template, and the fallback is recorded.

Disclosed limits. Some environmental receptor layers are structured placeholders pending authoritative replacements. They are marked as such wherever they contribute to a score, and upgrading them is tracked methodology work — not a silent patch.

Attribution and scoring are kept apart

When satellite radar detects an oil slick near assessed wrecks, the platform's job is source attribution: building and ranking the candidate list, corroborating it against an independent drift model, and putting the question in front of an analyst. What it does not do is quietly raise the risk score of every nearby wreck.

A detection changes a score in exactly one circumstance: a recurring release where a single wreck is the only plausible source. Everything else stays in the attribution record — visible, ranked and auditable, but outside the number a government will use to allocate survey budgets. Scores that inflate on ambiguity stop being trusted; the methodology is built to keep that from happening.

How the methodology is governed

WERP is maintained as a canonical specification with 38 numbered invariants — the properties of the scoring system that must hold, from "fixed band thresholds" to "a drift funnel can re-rank slick candidates but never add or remove one".

Any change to scoring follows a formal protocol: a written design note, a version bump, a dry-run rescore of the full inventory with a blast-radius audit of every score that would move, adversarial review, and sign-off — before anything reaches a live assessment. Every wreck's report shows the methodology version and revision it was scored under.

The specification is deliberately not published on the open web. It is available on request to sovereign partners, institutional reviewers and accredited researchers — request methodology access.

Change protocol

  1. Written design note
  2. Version and revision bump
  3. Dry-run rescore with blast-radius audit
  4. Adversarial review
  5. Sign-off, then — and only then — live rescore

Questions about the methodology?

Academic collaboration, methodology review, or access requests for the canonical specification.